Security by design for IoT devices

Mario Noseda, Lea Zimmerli, Andreas Rüst · Zürcher Hochschule für Angewandte Wissenschaften digital collection (Zurich University of Applied Sciences) · 2020

Unprotected IoT devices are an easy target for cyber-attacks. This white paper shows the application of a systematic development process to identify threats, derive security requirements and implement effective protection measures. The example of a simple WiFi-based sensor illustrates the design process and adequate protection measures. The latest generation of Secure Microcontrollers featuring Trusted Execution Environments (TEE) as well as Secure Elements both provide options to store key material securely and perform cryptographic operations in an energy-efficient way. The interaction of these hardware components together with dedicated firmware and a Public Key Infrastructure (PKI) enables a low-power sensor to connect securely to the cloud.

Read the paper · More papers on PaperTik